Set up sign-in. Let users get on with it.
Enable the methods you want — email, SMS, Google, or OAuth. Forte keeps the verification, sessions, and security work in one place.
Enable sign-in methods from the Forte dashboard
Give users a sign-in method that fits
Multi-factor authentication
Turn on MFA per project — optional for users who want it, or required on every sign-in. Users enroll and manage their own factors; you can reset MFA for a locked-out user from the console.
- Authenticator appsStandard TOTP — works with any authenticator app.
- Passkeys and security keysPhishing-resistant WebAuthn, bound to your domain.
- Email and SMS codesOne-time codes to any verified contact method.
- Single-use backup codesA recovery set users can regenerate at any time.
The email or phone a user signed in with can't double as their second factor — enforced, not advertised.
Sign-in works as before.
Users who enroll get challenged.
Every sign-in needs a second factor.
Give users control when something changes
Sessions, recovery, and security history are part of the account experience instead of a separate project.
- Forte provides APIs for users to list active sessions, sign out one device, or sign out everywhere.
- Login history with source IPs helps users review where they have signed in.
- Built-in audit trails record user actions.
- Administrate users, sessions, and MFA from the Forte console.
Screen sign-ins before they become a problem
Forte checks sign-ins for automated and abusive traffic by default, with nothing to configure.
- Automated bot and abuse detection on sign-in.
- Enabled by default — nothing to configure.